Annual Report · 2024

Our firstfull year.

2024 was a year of strengthening: our first-ever annual report, a formalised governance structure recognising the Corporation and Foundation as independent, co-equal organisations, and the first update to our support contract structure since 2019.

OpenSSL Corporation
2024
Annual Report
Security & Privacy for Everyone
— 2024 at a glance
15M+
downloads of the OpenSSL Library during 2024
88%
support contract renewal rate
18%
net customer growth, crossing the 100-customer milestone
$5.5M
total income — USD, from commercial support
— From the President

A message from our President.

For the past five years, we have delivered commercial support services, ensuring that businesses and organisations can securely use the OpenSSL Library. The income from commercial support funds the majority of ongoing development — and ensures that what we produce continues to evolve to meet modern security demands.

We have also financially supported the OpenSSL Foundation, allowing it to focus on its non-commercial activities and to grow into the organisation it is today. From OpenSSL 3.0 to 3.5, funding of the OpenSSL Project was almost exclusively the responsibility of the Corporation as income from donations to the Foundation dwindled; improved income has now let us expand that support.

We introduced new communication channels, including the Advisory Committees, to engage more deeply with those who rely on the projects under the OpenSSL Mission. I have been pleasantly surprised by the speed at which our communities have shown their enthusiasm in connecting with us and providing feedback.

We are just getting started. Our commitment remains unchanged: upholding our Mission to provide security and privacy tools for all.

Tim Hudson
Tim Hudson
President, OpenSSL Corporation
A first
First-ever annual report
2024 marked the Corporation's first published annual report.
Library reach
15M+
downloads in 2024 — found everywhere from dishwashers to satellites.
— Governance

A new governance structure.

After adopting our Mission and Values and recognising the varying needs of commercial and non-commercial communities, we formalised the governance structure of the two organisations.

The key change, on March 1, 2024, was officially recognising the OpenSSL Corporation and the OpenSSL Foundation as independent, co-equal organisations with distinct focuses — the Corporation on commercial communities and activities, the Foundation on non-commercial ones.

As part of this restructuring, the OpenSSL Management Committee (OMC) was dissolved effective March 1, 2024, and the OpenSSL Technical Committee (OTC) was scheduled for dissolution in April 2025.

To ensure strong governance, we expanded the voting membership to 10 individuals with long-term involvement in the OpenSSL Library, responsible for electing the Board of Directors.

Effective
March 1, 2024
Corporation and Foundation recognised as independent, co-equal organisations.
Voting members
10
long-term contributors empowered to elect the Board of Directors.
— Financial highlights

Financial stability.

FY2024 was marked by financial stability, a new support contract structure, and infrastructure investment. For the first time since 2019, we updated our support contract structure and pricing.

Total income
$5.5M
USD — reflecting expanded support contracts and service offerings.
Total expenses
$2.1M
USD across operations, engineering, and infrastructure.
Net revenue after taxes
$2.2M
USD — strengthening the Corporation's financial position.
Anton Arapov
Anton Arapov
Treasurer
— Support customers

Customer growth & retention.

Our customer base crossed the 100-customer milestone during FY24, with a renewal rate of 88% reflecting the strong value clients place on our services. Customers span top-tier enterprises, many generating billions in revenue.

88%
Renewal rate
+18%
Net customer growth
100+
Customers in FY24
>85%
Are large businesses
78%
North America
15%
EMEA
7%
APAC
— Engineering

A time-based release model.

The OpenSSL Library saw major advancements in 2024, with a transition to a time-based release model — demonstrating our ability to deliver predictable, on-time releases.

3.2
November 2023
Prior release in the time-based cadence.
3.3
April 2024
First scheduled release of 2024.
3.4
October 2024
Second scheduled 2024 release.
3.5
Planned April 2025
Next major planned release.
Tomas Vavra
Tomas Vavra
Engineering & Standards Manager
— 2024 at-a-glance

The year in numbers.

1,404
Issues closed
3,922
Commits
8
Releases
180k
Lines changed in GitHub
7
Webinars
1,400+
Webinar attendees
3
Conferences visited
264
OpenSSL Communities members
— Partnership

Partnership with Lightship Security.

In September 2024, the OpenSSL Corporation announced a strategic partnership with Lightship Security, a leading cryptographic security test lab and an Applus+ Laboratories company.

This collaboration establishes Lightship Security as the primary laboratory for FIPS 140-3 validations of the OpenSSL cryptographic library, ensuring a streamlined certification process. Beyond validations, Lightship also assists Corporation clients with rebrand certifications — simplifying compliance for vendors in regulated industries such as healthcare, finance, and ICT.

Cryptographic network connections — FIPS 140-3 validation
FIPS 140-3 validations with Lightship Security
Announced
Sept 2024
Primary lab for FIPS 140-3 validations of the OpenSSL Library.
Annual Report 2024

Read the full report.

The complete Annual Report 2024 covers governance, finance, engineering, customers, and community in full detail.